Privacy policy

RoboQuill for Shopify · Effective 3 July 2026

RoboQuill for Shopify ("the app") turns qualifying Shopify orders into real, posted handwritten cards, sent through the merchant’s own RoboQuill account. This policy explains what data the app touches, why, and what happens to it. It is written for the merchants who install the app and for their customers, whose details appear on the cards.

What we process, and why

When an order or customer event qualifies for a card, the app reads two kinds of data from the merchant’s Shopify store through Shopify’s API. It reads order details (number, status, totals, tags, and line items) to decide whether a campaign applies and to fill in the card’s text. And it reads the customer’s name, shipping address, and email, because that is the minimum a physical mailing needs: the name and address go on the envelope, and the name usually appears in the greeting.

This data has one purpose: producing the card the merchant configured. It is not used for advertising, profiling, or anything else, and it is never sold.

What we store

Recipient names and addresses are not stored. They are fetched from Shopify at the moment a card is prepared, passed to RoboQuill for printing and postage, and shown to the merchant in the app. The app’s own database keeps no copy.

What the database does hold is a send ledger: which order or customer received which card, its status, and its cost. This is the record that stops a customer being sent (and a merchant being charged for) the same card twice, and it contains order and customer IDs rather than names or addresses. Error text from failed sends can occasionally quote a fragment of an address, for example when an address fails validation; those fields are cleared automatically after 180 days, and immediately on a redaction request. The merchant’s RoboQuill API key is also stored, encrypted with AES-256-GCM, decrypted only in memory at the moment of sending, and never shown again after entry.

Who receives the data

Three parties handle the data. RoboQuill (roboquill.io) receives the recipient’s name, address, and card text under the merchant’s own RoboQuill account, in order to print and post the card; see RoboQuill’s own privacy policy for how it handles fulfilment data. DigitalOcean hosts the app and its database in London, with encryption in transit and at rest. Shopify is the source of the order and customer data, under the permissions the merchant granted at install. No other third parties receive personal data.

Retention and deletion

Security

All traffic uses TLS. The production database is a managed PostgreSQL instance with encryption at rest, reachable only from the app’s server over a private network. Credentials are encrypted at the application layer on top of that. Test and production environments are fully separate, with separate databases.

Contact

Questions, data requests, or complaints: hello@roboquill.io. We aim to answer within two working days.

We will update this page if the app’s data handling changes, and the effective date above will move with it.